All-source investigations

Table of contents
All-source investigations

What are all-source investigations?

All-source investigations combine every available category of relevant information — including cyber threat intelligence (CTI), open-source intelligence (OSINT), deep and dark web intelligence, financial intelligence, blockchain intelligence, attack surface management (ASM), corporate and company data, trade and customs data, sanctions and watchlists, and others — into a single, unified picture of illicit activity, rather than relying on any one data source in isolation.

An all-source investigation is a method for bringing every relevant category of information into one picture and deliberately checking each finding against the others before drawing a conclusion. The emphasis is on breadth and corroboration: no single input decides the outcome, and each new source either strengthens or challenges what the others show.

The approach has its roots in intelligence community doctrine. The National Institute of Standards and Technology (NIST) defines all-source intelligence as products or activities that incorporate all available sources of information — most commonly human, imagery, measurement and signature, signals, and open-source intelligence — into finished intelligence. The underlying principle is simple: any single collection discipline has blind spots, and an analyst who relies on one source is more exposed to gaps, deception, and confirmation bias than one who corroborates across several.

That same logic now guides work in law enforcement, national security, cyber threat intelligence, financial crime, fraud prevention, and corporate security. It applies whenever no single dataset can identify the people or organizations behind an act — whether the trigger is a victim complaint, a new vulnerability alert, a suspicious payment, a fake storefront, or a threat to a physical event.

Because it is a method rather than a product, all-source investigation is not limited to government agencies. A corporate security team piecing together an organized fraud ring, a threat-intelligence analyst mapping the infrastructure behind a phishing campaign, and a national security agency tracking a sanctioned network are all running the same basic play: gather independent sources, reconcile them, and follow the leads across domains until the picture resolves.

{{horizontal-line}}

How does all-source investigation work?

An all-source investigation rarely runs in a straight line. It works more like a loop that repeats and widens. An investigator takes a lead, tests it against independent sources, and — if it holds up — follows it into whatever domain it points to next, then runs the same test again from there. 

A flagged account leads to a Know Your Customer (KYC) record; the KYC record leads to a registered business; the business leads to a beneficial owner named on a sanctions list; that owner leads back to new accounts. Every turn of the loop is the same basic motion — corroborate, then pivot — and it repeats until the picture is complete enough to act on. The power comes from the sources being independent: each new one can either confirm what came before or contradict it, which is what guards against deception and confirmation bias.

Two things run continuously beneath that loop rather than as separate stages: building the network picture, and provenance.

Building the network picture: Entity resolution merges scattered identifiers (e.g. aliases, shell companies, front accounts, and, where digital assets are involved, pseudonymous wallet addresses) into single nodes for each person, group, or account, while link analysis draws the connections between those nodes (who controls what, who pays whom, how the pieces relate) so that isolated data points become a map of how the network actually operates.

Provenance: Every finding keeps a trail back to the source it came from, with consistent confidence language and a documented chain of custody, so the result stays defensible however many sources it draws on.

The investigation ends where the loop has produced enough corroborated, well-sourced attribution to support an action — an asset freeze, an infrastructure takedown, a regulatory referral, a prosecution, or an internal risk decision.

This mechanism reflects established intelligence tradecraft. The US and allied intelligence communities describe the broader workflow as the intelligence cycle — direction, collection, processing, analysis, and dissemination — and in the US intelligence community, Intelligence Community Directive 203 (ICD 203) sets the standard all-source analysts are held to, including that judgments draw on all available sources and describe source quality and uncertainty in consistent terms.

Automation and agentic tools increasingly assist throughout — pulling and normalizing data and surfacing correlations faster than manual review can. A human still sets direction, verifies findings, and authorizes action; the automation expands how much ground one analyst can cover.

{{horizontal-line}}

Why are all-source investigations important?

Serious threats rarely leave their evidence in one place. A fraud ring, a sanctioned procurement network, or a scam operation spreads its traces across accounts, companies, domains, identities, and — when money moves in crypto — public ledgers. Any one of those views, read alone, is partial and easy to misread. In its 2025 Internet Crime Report, the FBI's Internet Crime Complaint Center (IC3) recorded more than one million complaints for the first time, with reported losses of USD 20.9 billion — much of it driven by cross-border mule networks, shell companies, and layered cash-outs that no single dataset can explain on its own.

All-source investigation matters because it is the approach built to close those gaps. It lets an investigator:

  • Attribute activity to real-world entities, converting a fragmented, pseudonymous, or obscured trail into an identified individual, business, network, or state actor.
  • Corroborate weak signals. A single data point — an unusual transaction pattern, a newly registered domain, a name in a leaked dataset — is rarely conclusive on its own. Cross-referencing multiple sources turns a weak signal into a lead worth acting on.
  • Reduce false positives and false negatives that come from relying on any one detection method — a monitoring rule, a watchlist hit, or an open-source search — in isolation.
  • Produce results that hold up in front of whoever must rely on them — a court, regulator, board, or operational partner — because the conclusion rests on independent, corroborating sources rather than a single point.
  • Enable a wide range of disruptions, including freezing or recovering assets, taking down the web infrastructure behind a scam, revoking access, or interdicting a physical threat before it materializes.

The output of an all-source investigation is an attributed picture that different teams can act on in very different ways.

{{horizontal-line}}

Why do AI and agentic crime make all-source investigations more critical?

AI-enabled crime is rapidly increasing the speed, velocity, and impact of criminal activity. TRM Labs classifies criminal AI adoption into three tiers — horizon, emerging, and mature — with mature activity defined as AI systems that operate with minimal human input across tools like browsers, wallets, and email platforms, executing complex objectives largely on their own. We are already seeing this level of sophistication in cases around the world.

A single AI-enabled operation can now touch several domains — including identity, infrastructure, and financial channels — at once, at machine speed. For example:

  • Deepfake identity fraud. Synthetic voice, video, and image generation are used to bypass identity verification, impersonate executives, and defeat biometric checks — attacking the identity layer of an investigation before an investigator ever sees the financial or transactional layer.
  • Scripted, scaled social engineering. AI chatbots fine-tuned for romance and investment scams can run persuasive, personalized conversations with thousands of victims at once, feeding new accounts and money-movement channels into an investigation faster than manual review can flag them.
  • Automated evasion and layering. AI-driven tools can dynamically adjust transaction patterns, shell structures, or fund-movement paths to evade detection rules, whether the funds move through banks, shell companies, or crypto wallets.

Because an AI-enabled operation can span identity, infrastructure, and financial domains simultaneously, an investigator working from one data source will always be a step behind. All-source investigation is the method built to fuse those domains quickly enough to keep pace with an adversary that already operates across all of them.

{{horizontal-line}}

Who conducts all-source investigations?

All-source methods are used across the public and private sectors. The data sources and legal thresholds differ by mission, but the play is the same.

Law enforcement

Investigators combine forensic financial analysis with traditional case-building tools — subpoenaed records, search warrants, informant reporting, and financial-institution filings — to move from a victim complaint to an investigative lead and, ultimately, to court-ready proof. Where digital assets are involved, on-chain forensics becomes one of those inputs.

National security and intelligence

Agencies tracking sanctioned actors, proliferation financing, state-sponsored activity, or threats to major public events fuse signals intelligence, cyber threat intelligence, human reporting, and financial data to build a complete operational picture — often to interdict a plot or a shipment before it happens.

Cyber threat intelligence

Analysts map the people and infrastructure behind intrusions, phishing, and scam operations by correlating domain and hosting data, malware artifacts, communications data, and open-source research — work that can lead to taking down the infrastructure running a fraudulent platform.

Financial crime and compliance teams

Banks, fintechs, and crypto businesses combine transaction monitoring and account or wallet screening with KYC records, adverse media, and sanctions screening to meet anti-money laundering (AML) obligations and to decide whether to file a suspicious activity report. This is one important application of all-source methods — not the whole of them.

Corporate security and fraud teams

Private sector teams run all-source investigations to protect their own organizations. A retailer facing an organized refund-fraud ring, for example, can combine internal transaction and account data with device signals, open-source research on the actors, and public business records to identify the network and cut off its access — the same method as a government investigation, aimed at a commercial threat.

Regulators and policymakers

Supervisors draw on financial data, corporate filings, licensing records, and public complaints during examinations and enforcement actions to judge whether a supervised entity's controls are adequate and whether specific conduct warrants action.

{{horizontal-line}}

What data sources feed all-source investigations?

The categories below are the ones investigators draw on most often — not a fixed or complete list. An all-source investigation pulls in whatever is relevant to the case, which can also include geospatial and imagery data, travel and telecommunications records, device and sensor data, or human-source reporting, among others.

Data source Examples
Cyber threat intelligence (CTI) Malware artifacts; hosting and infrastructure fingerprints; and the tools, tactics, and procedures behind an intrusion, phishing campaign, or scam operation
Open-source and social media intelligence (OSINT/SOCMINT) Publicly available web content, social media activity, and forum-based information that can corroborate an identity, location, or affiliation
Deep and dark web intelligence Marketplace listings, breach dumps, and forum activity not indexed by standard search; often the first signal of a compromised credential or emerging scheme
Financial intelligence (FININT) Transaction records, banking data, and payment-rail activity held by financial institutions
Identity intelligence Records that resolve aliases, breached credentials, and device or account signals — including KYC data held by financial institutions — into a single verified identity
Corporate and beneficial ownership data Registries that reveal who owns or controls a company, often used to unwind shell company structures
Sanctions and watchlist data Government and international lists used to screen individuals and entities for sanctions or PEP exposure
Geospatial and trade intelligence Location data, shipping manifests, and customs records that place people, goods, or funds at a specific place and time
Blockchain intelligence On-chain transaction data, wallet clustering, and cross-chain tracing across public ledgers; relevant whenever a case involves virtual asset service providers (VASPs) or crypto-denominated assets

Each category is important, but none tells the whole story alone. An identity record without financial data is just a name. A corporate registry without transaction data misses the movement of funds. Sanctions data without transaction tracing misses evasion through intermediaries. All-source investigation treats each category as one input into a single reconciled record.

{{horizontal-line}}

What are the challenges of conducting all-source investigations?

Challenge How it slows down investigations
Data fragmentation Each category typically lives in a different tool, format, and vendor relationship, which forces analysts to spend significant time reconciling data by hand rather than analyzing it.
Jurisdictional and legal constraints Cross-border data sharing is often slower than the crime it's meant to address, particularly when funds move across multiple countries in minutes.
Evidentiary consistency Sources vary in reliability, so every finding needs provenance — a documented trail from each conclusion back to the underlying source it rests on. Preserving that provenance, together with a documented chain of custody and consistent confidence language, is what keeps a conclusion built from several sources defensible: anyone reviewing it can trace where each element came from, how reliable it is, and how the judgment was reached.
Analyst capacity and specialization Case volumes are growing faster than investigative headcount. All-source work also demands fluency across very different disciplines, including financial forensics, corporate registries, OSINT, cyber infrastructure, and on-chain analysis. Few analysts or teams have deep expertise in all of them.
Evolving evasion tactics Criminals actively exploit the seams between data categories — for example, using a legitimate-looking corporate structure to obscure a beneficial owner's true identity — which is precisely the kind of gap all-source methods are designed to close.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. What is the difference between all-source and single-source investigations?

A single-source investigation draws its conclusions from one type of data — transaction records alone, for example. An all-source investigation deliberately combines multiple independent data types — financial, identity, corporate, sanctions, infrastructure, open-source, and, where relevant, blockchain data — and cross-checks findings across them before reaching a conclusion.

2. Where does the term "all-source" come from?

It comes from military and intelligence-community doctrine, where an all-source product is built from every available collection discipline — human, signals, imagery, and open-source intelligence — rather than any single one. Investigators in law enforcement, national security, and the private sector have adapted the same principle to their own data.

3. What data types are combined in an all-source investigation?

Typical inputs include identity and KYC records, corporate and beneficial-ownership registries, sanctions and watchlist data, cyber infrastructure data such as domain registration history, open-source and dark-web intelligence, and, in cases involving digital assets, blockchain data.

4. Do only government agencies run all-source investigations?

No. Any organization with access to more than one category of information can run one. Corporate security teams, fraud and threat-intelligence units, and financial institutions all use all-source methods to identify the actors and networks behind a threat to their business or customers.

5. How do investigators verify findings when sources differ in reliability?

They apply consistent confidence language to describe how certain each finding is, document the chain of custody for every piece of evidence, and favor methods that show their underlying basis rather than presenting a conclusion without support. Corroboration across independent sources is what raises confidence.

6. What is a "cross-domain pivot"?

A cross-domain pivot is the moment an investigation moves from one data type to another based on a discovered link — for example, from a flagged account to a KYC record, then to a registered business, then to a beneficial owner on a sanctions list. In cases involving digital assets, a pivot might instead begin from a wallet address. Real investigations usually require several pivots before reaching a conclusion.

7. Do all-source investigations require special legal authority to access data?

Often, yes. Publicly available and open-source data can be gathered freely, but many off-chain sources — KYC records, banking information, corporate filings — require a subpoena, search warrant, mutual legal assistance treaty request, or a regulatory information-sharing arrangement, depending on the jurisdiction and the type of case.

8. How do all-source methods help disrupt threats and recover assets?

By attributing an account, entity, wallet, or piece of infrastructure to a real-world individual or organization, investigators can act before harm compounds — freezing or seizing assets, taking down malicious infrastructure, revoking access, or interdicting a plot. All-source methods shorten the path from "something is wrong" to "we know who, and we can act."

9. What role does open-source intelligence (OSINT) play?

OSINT — information from websites, social media, forums, and public records — often provides the corroborating detail that turns a financial or transactional lead into an identified individual or organization, particularly when combined with domain and infrastructure data.

Subscribe and stay up to date with our insights

Access our coverage of TRON, Solana and 23 other blockchains

Fill out the form to speak with our team about investigative professional services.

Services of interest
Select
Transaction Monitoring/Wallet Screening
Training Services
Training Services
 
By clicking the button below, you agree to the TRM Labs Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No items found.